China Data Export Security Assessment Measures
In force China · In force Sep 1, 2022 · no upcoming deadlines
Deadlines
| Date | What happens | When |
|---|---|---|
| Mar 1, 20233 years ago | Remediation window for existing transfers endstentative | 3.6 years ago |
| Sep 1, 20224 years ago | Security assessment measures take effect | 4.1 years ago |
Summaries for reference, not legal advice. Check the official text.
What it does
Sets the CAC security assessment that must be passed before certain data leaves China, including exports of important data and large-scale personal information exports. Data handlers must run a self-assessment, then apply through the provincial CAC for a national CAC review. Transfers already under way had six months to come into compliance.
- Who it applies to
- Data handlers exporting important data, CII operators exporting personal information, and handlers exporting personal information above the volume thresholds set by the CAC.
- Penalties
- Handled under the CSL, DSL and PIPL. PIPL fines reach RMB 50 million or 5% of prior-year turnover for serious violations.
- Enforced by
- Cyberspace Administration of China (CAC)
- Official name
- Measures for the Security Assessment of Outbound Data Transfers
- Citation
- CAC Order No. 11
- Topics
- data-residency, privacy, cybersecurity
Verified 2026-09-25 gov.cn
Research notes
The 2024 Provisions on Promoting and Regulating Cross-Border Data Flows (cn-cross-border) raised the thresholds and extended approval validity from 2 to 3 years. Signed 2022-07-07.
Related
Questions about China Data Export Security Assessment Measures
- What are the China Data Export Security Assessment Measures compliance deadlines?
- Sep 1, 2022: Security assessment measures take effect. Mar 1, 2023: Remediation window for existing transfers ends (tentative).
- When does China Data Export Security Assessment Measures take effect?
- China Data Export Security Assessment Measures took effect on Sep 1, 2022.
- Who does China Data Export Security Assessment Measures apply to?
- Data handlers exporting important data, CII operators exporting personal information, and handlers exporting personal information above the volume thresholds set by the CAC.
- What are the penalties under China Data Export Security Assessment Measures?
- Handled under the CSL, DSL and PIPL. PIPL fines reach RMB 50 million or 5% of prior-year turnover for serious violations.